Files
headquarter/openspec/changes/live-config-profile-refresh/design.md
Developer add7c1b500 feat: add live config profile refresh
- Standardize built-in tool users for shared writable profile mounts
- Mount canonical non-Git profile sources across compatible instances
- Report restart-required outcomes and guard active profile deletion
- Surface restart feedback in config profile editing

Quality gates: frontend build passed; backend py_compile and LSP passed.
Skipped: backend pytest/Ruff unavailable; Docker/manual checks not approved.
2026-07-21 11:12:41 +00:00

1.2 KiB

Design: Live Config Profile Refresh

Canonical working copies

Each non-Git Config Profile owns canonical host-side storage. Directory mounts use canonical profile directories; each top-level profile file uses a canonical host file bind-mounted under the container working directory. All compatible instances selected for the profile mount the same sources, so UI and container edits are immediately shared.

Container compatibility

Supported built-in tools standardize on one non-root user/group. Existing instances retain their current image/user and report restart_required. Custom tools are not rewritten; tools that do not opt into the shared user/group return incompatible_permissions.

Save behavior

A profile save writes canonical profile files atomically per file. The save response reports affected compatible instances, restart_required topology/runtime changes, incompatible_permissions, and detectable overwrite warnings. Last writer wins; no merge or lock protocol is imposed.

Scope boundaries

Git mount mutation is explicitly deferred. Workspace/repository mounts are never changed. Profile deletion is rejected while running instances still use the profile.